Data embassies: The new face of sovereignty washing?
Critical infrastructure as a site for casualty
In March 2026, drone strikes hit Amazon Web Services (AWS) data centres in West Asia. Following this, airports froze, the stock market shut, and businesses stalled. For millions of people, daily life simply switched off, just because a data centre had become a military target.
This is not the first time a country has learned that digital infrastructure can become a casualty of conflict. Estonia spent years fending off Russian cyberattacks. Most notoriously, in 2007, a wave of attacks knocked out banks, newspapers, and government websites. It took a series of such attacks before the country considered storing its critical data abroad. After years of negotiating, building, and formalising, Estonia signed an agreement in 2017 to establish a data embassy in Luxembourg.
Today, with increasing geopolitical instability, this model is being pitched as a ready-made fix for a growing fear that a country's most critical data (government records, financial systems, citizen infrastructure) could be wiped out, held hostage, or simply go dark in a conflict. Global South nations such as Saudi Arabia and India are among those now racing to adopt it. But a closer look reveals that data embassies risk being masqueraded as a sovereignty solution – all form, no substance.
The making of a sovereign solution
The premise is simple: a country stores its most critical government data like citizen records, financial systems, and business registries on servers physically located in another country, but under its own laws and jurisdiction. This means that even if the host country is invaded, destabilised, or turns hostile, the data remains legally and operationally under the home country's control.
The pitch is compelling: a government in exile could theoretically continue functioning because its digital infrastructure remains intact and untouchable outside its geographic boundaries. In short, it is a bet that legal jurisdiction can substitute for physical control.
For years, the idea remained niche. Monaco followed Estonia’s lead in 2021, setting up its own data embassy in Luxembourg. Bahrain became the only country to pass a data embassy law in 2018, positioning itself as a neutral digital ground where others could build data embassies. India began exploring similar arrangements with the UAE while Singapore looked at establishing a presence in India’s Gujarat International Finance Tec-City (“GIFT City”).
Then came the sovereign AI race and the war in West Asia (“Iran war”), and the conversation accelerated sharply. With its draft Global AI Hub Law in April 2025, Saudi Arabia became the first G20 nation to propose a comprehensive legal framework for data embassies. Yet, a closer look reveals that Saudi Arabia is not looking to protect its own data from foreign threats. Instead, it is looking to be a host where other countries park their data, attracted by political stability and modern infrastructure. Bahrain had taken a similar position. Both countries are presenting themselves not as sovereignty-seekers but as sovereignty-sellers, betting that a fragmenting world will need neutral ground and that there are money and influence to be made in providing it. Data embassies had quietly shifted from being a defensive tool for threatened nations into a commercial sovereign commodity.
Sovereign in name, dependent in practice
The Estonia model, the inspiration behind this entire debate, was not fully sovereign to begin with. Microsoft helped ensure its technical viability, while private partners like Dell EMC, Ericsson, and Telia helped support the cloud infrastructure. As it turns out, the world’s most celebrated data sovereignty project runs on a distinctly non-sovereign stack.
The pattern repeats for newer projects. Saudi Arabia’s data embassy ambitions are being built on deals and agreements with Big Tech companies like Nvidia, Google, and Oracle. So, the stack, if realised, would run on American chips, American cloud platforms, and American software.
This is the same sleight of hand as buying a sovereign cloud from a hyperscaler and calling it independence. Grohmann and Costa Barbosa (2025) have termed this "sovereignty-as-a-service" – a process by which Big Tech companies strategically co-opt and redefine digital sovereignty, repackaging it as a modular product delivered through proprietary infrastructure. Rather than sovereignty being exercised over platforms, it is provisioned by them, on their terms. Data embassies, built on the same infrastructure, carry on this same legacy.
Importing a flawed model
Despite their documented practical limitations, data embassies are painted as promising for Global South countries. India is exploring a data embassy arrangement with the UAE. Singapore is in conversations about establishing a presence in India’s GIFT City. These are framed as South-South sovereignty wins, where the developing world is building digital resilience on its own terms.
Yet replicating the Estonian model requires prerequisites that most Global South countries lack. Estonia spent decades investing in and implementing e-governance and digital infrastructure across its society. That foundation is not something that most countries can conjure quickly, or at all. Without this digital architecture, Luxembourg’s political stability as a host, and the EU’s legal scaffolding protecting both parties, the model would have failed.
The Global South is attempting to fast-track this idea without laying the necessary groundwork. Data embassies demand digital architectures and stable political environments, both necessitating long-term investments. They also need a supranational legal architecture to backstop bilateral agreements. The absence of a standard legal framework compounds the problem. Since no standardised legal model exists to govern data embassies, each arrangement requires a bilateral treaty detailing jurisdiction, oversight, and access limitations, all of which depend on sustained trust between states. At a time when global conflict is at an all-time high, that trust is precisely what is in short supply.
Conclusion
The appeal of data embassies is understandable. After watching data centres burn in the Gulf, governments want to act. Data embassies offer something rare in digital policy – a concrete, nameable solution. Sign a bilateral agreement, build a facility, declare sovereignty. It feels like progress.
Yet, the promise of a data embassy is only as strong as the bilateral treaty underpinning it, the stability of whoever hosts you, and the goodwill of the private companies running the infrastructure – the same companies whose centralised architecture created the vulnerability in the first place. When any of those three fails, the embassy fails with them.
The real risk is not that data embassies fall short; instead, it's that they succeed just enough for governments to stop asking who controls the chips, who owns the cloud, and what happens when their interests diverge from yours.